A cloud-based identity and access management service for securing user authentication and resource access
Entra passkey registration sends hints ["security-key"] on Linux, blocking synced passkeys (1Password)
We have a passkey profile that allows synced passkeys (no attestation, no AAGUID restrictions). Users can register 1Password passkeys from macOS, but not from Linux (Chrome and Edge): Security info > Add sign-in method > Passkey always opens the hardware-key dialog instead of 1Password.
The fido/create page sends hints: ["security-key"] to Linux user agents and ["client-device"] to macOS. If only that hint is removed client-side, 1Password registers the passkey and Entra accepts it as "Passkey (Synced)".
Is this intended? Is there a supported way to register synced passkeys from Linux?
The FIDO2 compatibility matrix lists Linux Chrome/Edge as supported and synced passkeys as GA, with no Linux exception.